Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,051cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,175GitHub PoC 14,092VulnCheck XDB 8,604Nuclei 4,255Metasploit 3,474✓ verified onlyrecentpopularrisk
77,012 exploits
VulnCheck XDB
initial-access
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISK
open ↗GitHub PoC★ 4
is a PoC tool designed to exploit an authenticated Remote Code Execution (RCE) vulnerability in specific versions of PostgreSQL (9.3 - 11.7)
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open ↗GitHub PoC★ 5
The CVE-2019-16172 Scanner is designed to check LimeSurvey instances for the stored XSS vulnerability.
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, Su
23RISK
open ↗GitHub PoC★ 6
CVE-2024-26304 is a critical vulnerability (CVSS score of 9.8) affecting ArubaOS
There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated r
60RISK
open ↗GitHub PoC★ 139
Zimbra - Remote Command Execution (CVE-2024-45519)
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISK
open ↗VulnCheck XDB
initial-access
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open ↗VulnCheck XDB
infoleak
SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The
63RISK
open ↗VulnCheck XDB
initial-access
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISK
open ↗GitHub PoC★ 3
Python implementation of a tool for decrypting and encrypting sensitive data in Grafana, specifically addressing the vulnerabilities associated with CVE-2021-43798. Grafana encrypts all data source passwords using the AES algorithm with the secret_key found in the defaults.ini configuration file.
Grafana path traversal
100RISK
open ↗GitHub PoC★ 4
A simple Python script to test an off-by-one vulnerability in the OPIE library (CVE-2010-1938). This vulnerability affects certain FTP servers and may allow for Denial of Service (DoS) or arbitrary code execution.
Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeB
28RISK
open ↗VulnCheck XDB
client-side
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open ↗VulnCheck XDB
infoleak
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RISK
open ↗GitHub PoC★ 2
Simple hash cracker for Apache Shiro hashes written in Golang. Useful for exploiting CVE-2024-4956.
Nexus Repository 3 - Path Traversal
61RISK
open ↗VulnCheck XDB
initial-access
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RISK
open ↗GitHub PoC
EuJin03/CVE-2021-4034-PoC
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open ↗VulnCheck XDB
local
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open ↗VulnCheck XDB
remote-with-credentials
An Authenticated Remote Code Execution (RCE) vulnerability affects the TP-Link Archer router series. A vulnerability exi
53RISK
open ↗GitHub PoC★ 3
A Bash script designed to scan multiple domains for the CVE-2024-4577 vulnerability in PHP-CGI.
Argument Injection in PHP-CGI
100RISK
open ↗GitHub PoC
Exploit of CVE-2021-23639 for the vulnerable library 'md-to-pdf' in JS
Remote Code Execution (RCE)
48RISK
open ↗GitHub PoC★ 1
Woo Inquiry <= 0.1 - Unauthenticated SQL Injection
Woo Inquiry <= 0.1 - Unauthenticated SQL Injection
63RISK
open ↗VulnCheck XDB
client-side
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open ↗GitHub PoC★ 2
Nortek Linear eMerge E3 Pre-Auth RCE PoC (CVE-2024-9441)
Linear eMerge e3-Series Forgot Password Command Injection
60RISK
open ↗VulnCheck XDB
local
Kernel: io_uring: page use-after-free vulnerability via buffer ring mmap
46RISK
open ↗GitHub PoC★ 3
CVE-2023-41425 (Wonder CMS XSS to RCE) exploit which serves required scripts locally. Good if you're lost at sea and have found a problem with your bike.
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISK
open ↗GitHub PoC★ 5
This Python script helps to detect the Etherleak (CVE-2003-0001) vulnerability on a target host by analyzing the padding data in network packets. The script uses Scapy to send various types of requests (ICMP, ARP, or TCP) and checks if the responses contain any padding data that could potentially leak sensitive memory contents.
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote att
45RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.